Attending CrowdStrike Day Zero 2026 in Las Vegas, NV? Meet the VulnCheck team, proud sponsors of the official Threat Research Summit Pool Party. From August 30 to September 1, threat researchers and industry veterans will collaborate on everchanging perspectives on the future of exploit intelligence. Interested in joining? Details: https://lnkd.in/gdDUswap
VulnCheck
Computer and Network Security
Lexington, MA 13,341 followers
Outpace Adversaries
About us
VulnCheck helps organizations outpace adversaries with exploit intelligence that predicts avenues of attack with speed and accuracy. The VulnCheck team comprises a who's who of cybersecurity research, with decades of experience uncovering 100s of 0days and 10+ patents. VulnCheck's vulnerability and exploit intelligence equips defenders with the insights they need to focus resources on the vulnerabilities that matter most. That's why VulnCheck has been selected to power government agencies, large enterprises, and the industry's most innovative cybersecurity solutions, covering billions of assets around the world. See what you're missing at www.vulncheck.com.
- Website
-
https://vulncheck.com
External link for VulnCheck
- Industry
- Computer and Network Security
- Company size
- 51-200 employees
- Headquarters
- Lexington, MA
- Type
- Privately Held
- Founded
- 2021
- Specialties
- vulnerability management, threat intelligence, vulnerability intelligence, exploit intelligence, and cyber threat intelligence
Locations
-
Primary
Get directions
Lexington, MA 02420, US
Employees at VulnCheck
Updates
-
The vulnerability landscape is shifting. Join us on Wednesday, August 26 at 12 p.m. CT for the latest In the Wild with VulnCheck webinar. Patrick Garrity 👾🛹💙 and kimber D. explore how less CVE enrichment, mounting regulatory pressure, and AI-generated vulnerable code are creating new challenges for security teams -- and what it means for vulnerability prioritization and reporting. Register: https://lnkd.in/gvKJDQd6
Regulation, NIST's data pullback, and AI-generated code are colliding in 2026. On August 26th, join Patrick Garrity 👾🛹💙 and kimber D. as they break down what it means for how security teams prioritize and report.
Regulation, Data Gaps, and AI Are Colliding
www.linkedin.com
-
VulnCheck recently uncovered ENDLESSDOORS, a pre-installed command-and-control implant found in Zbtlink router firmware that phones home and can provide operators with remote root access. The implant was identified across 20+ router models and years of firmware images, including devices sold under multiple brands. Read the full research from VulnCheck CTO Jacob Baines: https://lnkd.in/dBZHNdxt
-
-
The THREATCON1 2026 agenda is now available! Join us October 5–7 in Reston, VA for three days of technical workshops, speaking tracks, Capture the Flag, networking, and a keynote from Gen. Paul Nakasone. Check out the agenda and don't forget to register to attend THREATCON1: https://lnkd.in/ghdG9s9h
-
-
VulnCheck reposted this
❗New #KEV: Earlier today, VulnCheck's Canary network started seeing malicious scanning for CVE-2026-25895, a critical path traversal #vulnerability in SCADA / OT management dashboard FUXA. Successful exploitation gives a remote, unauthenticated attacker a file write primitive, which the VulnCheck research team used to drop a root shell in our prior testing. 🌐 The activity we've seen so far is limited to a single IP, which appears to be conducting broad internet scanning for vulnerable FUXA instances. The attacker request attempts to overwrite main.js with junk data via the CVE-2026-25895 path traversal. No #RCE payloads dropped yet. 📈 Our Canaries have also detected exploitation of several other FUXA vulnerabilities over the past year, including CVE-2026-25939 (authorization bypass RCE) and CVE-2023-33831 (remote command execution), the latter of which has copious activity dating back to November 2025 and as recently as yesterday. VulnCheck Target Intelligence finds about 60 FUXA installations on the public internet. An exploit, PCAP, Suricata/Snort rules, and a target Docker container were available to VulnCheck Initial Access Intelligence customers on July 25, 2026. More KEVs (free): https://lnkd.in/eeqZzQVD
-
-
VulnCheck researcher Valentin Lobstein (Chocapikk) recently disclosed CVE-2026-14863, an OS command injection vulnerability affecting FileRun. The flaw could allow authenticated attackers with upload permissions to achieve remote code execution through malicious filenames, while certain public file-request configurations may also enable exploitation without an account. Read the full technical analysis: https://lnkd.in/gjuxUjEb
-
Heading to Amsterdam for RLBN Europe 2026? Meet VulnCheck Sept. 2–4. As a Quantum Tier Partner and sponsor, we’ll be on site sharing real-world exploit intelligence and threat insights. Stop by the VulnCheck exhibit table to meet the team and grab some exclusive swag, then join us at the AfterFuse party for an evening of networking with cybersecurity leaders, researchers, and practitioners. Learn more: https://lnkd.in/gZQuRvmp
-
-
What happens when reduced CVE enrichment, tighter regulatory timelines, and AI-generated vulnerable code hit at once? Join Patrick Garrity 👾🛹💙and kimber D. for the August edition of In the Wild with VulnCheck webinar on Wednesday, August 26 at 12 p.m. CT. They’ll break down what these shifts mean for how security teams prioritize, report, and keep pace. Register: https://lnkd.in/gvKJDQd6
Regulation, NIST's data pullback, and AI-generated code are colliding in 2026. On August 26th, join Patrick Garrity 👾🛹💙 and kimber D. as they break down what it means for how security teams prioritize and report.
Regulation, Data Gaps, and AI Are Colliding
www.linkedin.com
-
A hidden “phone home” implant found in more than 20 Chinese-made router models raises questions about how it worked, who could control it, and who may be affected. VulnCheck CTO Jacob Baines, who discovered ENDLESSDOORS, joined DW News to explain how the backdoor phones home and can give whoever answers remote control. The Register’s Simon Sharwood added context on who uses these devices and the broader implications. Watch: https://lnkd.in/g4hyg6qK
Could your internet router be compromised? | DW News
https://www.youtube.com/
-
VulnCheck ranked No. 478 on the 2026 #Inc5000 list, which recognizes America’s fastest-growing private companies. With 717% three-year revenue growth, we placed in the top 10% overall and among the top 10 cybersecurity companies on the list. The recognition reflects growing demand for exploit intelligence that helps security teams focus on vulnerabilities actively weaponized in the wild. Thank you to our customers, partners, and team for making this possible. Learn more here: https://lnkd.in/gfyyD_SX